U.S. agencies expand PLC-targeting warning and guidance
Public Sector Action
Summary
Hide ▲
Show ▼
U.S. agencies and CISA expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers, raising immediate operational risk for critical-infrastructure operators and PLC manufacturers. The warning named Rockwell Automation, Schneider Electric, and Siemens as examples of affected vendors. CISA also paired the alert with defensive steps for operators exposed to industrial-control access paths.
Related Happenings
CISA, ACSC, and FBI release CI Fortify isolation guidance for critical infrastructure
Public Sector Action
H score28
First: 28.07.2026 21:41
Last: 28.07.2026 21:41
Sources 1
About this happening:
CISA, ACSC, the FBI, and partners released CI Fortify – Advice for isolating vital systems for critical infrastructure operators. The guidance tells organizati...
CISA, ACSC, and FBI release CI Fortify isolation guidance for critical infrastructure
Public Sector ActionAbout this happening: CISA, ACSC, the FBI, and partners released CI Fortify – Advice for isolating vital systems for critical infrastructure operators. The guidance tells organizati...
CISA-led joint advisory to secure internet-exposed ATG systems
Public Sector Action
H score43
First: 05.06.2026 17:50
Last: 05.06.2026 17:50
Sources 1
About this happening:
On 2026-06-05, CISA, the FBI, the NSA, the Department of Energy, and other U.S. partners issued a joint advisory telling critical infrastructure organiza...
CISA-led joint advisory to secure internet-exposed ATG systems
Public Sector ActionAbout this happening: On 2026-06-05, CISA, the FBI, the NSA, the Department of Energy, and other U.S. partners issued a joint advisory telling critical infrastructure organiza...
CISA KEV directive for CVE-2026-20133
Public Sector Action
H score36
First: 21.04.2026 15:30
Last: 21.04.2026 15:30
Sources 1
About this happening:
On Monday, April 21, 2026, CISA added CVE-2026-20133 to the KEV Catalog and ordered FCEB agencies to secure their networks by Friday, April 24. The directi...
CISA KEV directive for CVE-2026-20133
Public Sector ActionAbout this happening: On Monday, April 21, 2026, CISA added CVE-2026-20133 to the KEV Catalog and ordered FCEB agencies to secure their networks by Friday, April 24. The directi...
CISA April 7 Rockwell Automation/Allen-Bradley PLC mitigation advisory
Advisory/Mitigation
H score32
First: 08.04.2026 11:15
Last: 08.04.2026 11:15
Sources 1
About this happening:
CISA’s April 7 mitigation advisory on internet-facing OT assets now also covers an ongoing Iranian cyber campaign against US critical infrastructure. In the ...
CISA April 7 Rockwell Automation/Allen-Bradley PLC mitigation advisory
Advisory/MitigationAbout this happening: CISA’s April 7 mitigation advisory on internet-facing OT assets now also covers an ongoing Iranian cyber campaign against US critical infrastructure. In the ...
Iranian-affiliated US CNI OT attack campaign
Campaign
H score33
First: 08.04.2026 11:15
Last: 08.04.2026 11:15
Sources 1
About this happening:
An Iranian-affiliated campaign is targeting internet-exposed industrial systems at US critical infrastructure organizations, with activity seen against Rockwell Auto...
Iranian-affiliated US CNI OT attack campaign
CampaignAbout this happening: An Iranian-affiliated campaign is targeting internet-exposed industrial systems at US critical infrastructure organizations, with activity seen against Rockwell Auto...
Timeline
-
29.07.2026 16:48 2 articles · 2h ago
U.S. agencies expand warning on Iranian-affiliated PLC targeting
Industry Or Public Sector UpdateU.S. agencies and CISA expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers made by Rockwell Automation, Schneider Electric, Siemens and potentially other manufacturers, and recommended logging cellular modem connections, restricting controller access to authorized systems, inspecting running project files for unauthorized changes, validating backups before restoration, and returning controllers with physical mode switches to run mode only after validation.
Show sources
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline — thehackernews.com — 29.07.2026 16:48
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline — thehackernews.com — 29.07.2026 16:48